
User management
Page 56
FortiRecorder 2.4.2 Administration Guide
Trusted hosts
Type the IP address and netmask from which the account is allowed to
log in to the FortiRecorder appliance. You can specify up to 10 trusted
network areas. Each area can be a single computer, a whole subnet, or
a mixture.
To allow login attempts from any IP address, enter
0.0.0.0/0
.
To allow logins only from a single computer, enter its IP address and a
32-bit netmask, such as:
172.168.1.50/32
Caution:
If you configure trusted hosts, do so for
all
accounts. Failure
to do so means that all accounts are still exposed to the risk of brute
force login attacks. This is because if you leave even
one
account
unrestricted (i.e.
0.0.0.0/0
), the FortiRecorder appliance must allow
login attempts on all network interfaces where remote administrative
protocols are enabled, and wait until
after
a login attempt has been
received in order to check that user name’s trusted hosts list.
Tip:
If you allow login from the Internet, set a longer and more complex
, and enable only secure administrative access protocols
) to minimize the security risk. For information on
administrative access protocols, see
Tip:
For improved security, restrict all trusted host addresses to single
IP addresses of computer(s) from which only this administrator will log
in.
Type
Select either:
•
Administrator
— Suited to network technicians or administrators.
The account has full access to configure all FortiRecorder NVR
network and camera settings, create accounts, receive all
notifications via email, and view live video feeds and previous
recordings from all cameras.
•
Operator
— Suited to an office manager or perhaps security
guard. The account can view assigned live camera feeds and
associated previous recordings, including camera-based
notifications via email (“snapshot notifications”). It can change its
own password, but otherwise
cannot
change the FortiRecorder
NVR or camera configuration, reducing risk of accidental
misconfiguration.
•
Viewer
— Suited to a security guard. Only assigned live camera
feeds. It
cannot
view previous recordings, and therefore cannot
receive snapshot notifications. It can change its own password, but
otherwise cannot change the FortiRecorder NVR or camera
configuration.
This option does not appear for the
admin
administrator account,
which by definition is always an administrator.
Setting name
Description